2025 · Full-Stack Developer
Amoako's Passwords
Zero-Knowledge Password Manager
- Discipline
- Coding
- For
- Fun
- Stack
- Next.js 15TypeScriptGoPostgreSQLRedisAES-256-GCMPBKDF2bcryptArgon2JWT
- Links
- GitHub
Problem
Password managers are only as trustworthy as what the server can see.
What I built
A zero-knowledge vault: AES-256-GCM in the browser, a Go REST API, PostgreSQL, Redis rate limiting and a security dashboard.
Result
8 shipped pages, import/export, and a server that only ever stores ciphertext.
Built a production-grade zero-knowledge password manager with enterprise-level encryption and auth
What went into it
- Developed a full-stack password manager using Next.js 15 (TypeScript, shadcn/ui, Framer Motion) and a Go REST API, implementing a zero-knowledge architecture where all vault data is encrypted client-side via AES-256-GCM before any server transmission.
- Designed and implemented a PostgreSQL database schema covering passwords, WiFi credentials, categories, sessions, and audit logs; integrated Redis for session storage and rate limiting across all API endpoints.
- Shipped 8 functional pages including a security dashboard, WiFi password manager, and CSV/JSON import-export for seamless data portability.
- Implemented enterprise-grade authentication using PBKDF2 key derivation, bcrypt/Argon2 password hashing, and a custom JWT service for access and refresh tokens.
How I thought about it
Everything sensitive is encrypted before it leaves the browser, so the server stores data it can't read. That rules out server-side search, which I accepted on purpose.
